Crypto news

11.08.2026
23:17

North Korea has embedded the laundering of stolen cryptocurrency into global scam networks: a new level of threat.

северокорейские хакеры North Korean hackers

An analysis I conducted as part of a defense institute study has uncovered a troubling trend: North Korea has radically changed its approach to laundering stolen digital assets. Instead of creating isolated channels, state-backed hackers are now actively integrating into existing criminal financial ecosystems. This is not just an evolution, but a qualitative leap in laundering efficiency.

This involves a comprehensive infrastructure that includes over-the-counter (OTC) platforms, P2P traders, illegal exchanges, mixers, and cross-chain bridges. The key finding: from January 2024 to September 2025, Pyongyang stole at least $2.8 billion in virtual assets. These funds directly fuel the weapons program, and, critically, the stage of conversion into fiat currency remains the least studied link in the entire chain.

From hackers to criminal intermediaries

After the initial breach, North Korean operators are increasingly handing assets over to third-party launderers. A telling example is the $1.5 billion hack of the Bybit exchange in February 2025. The "whitening" process involved an entire network of OTC and P2P traders, mostly Chinese citizens, who fragmented and moved assets around the clock. By September 2025, according to international monitoring groups, all stolen funds had been successfully cashed out. Meanwhile, the assets pass through dozens of addresses and several blockchains, completely obscuring the trail.

Scams as part of the ecosystem

The most alarming aspect is the symbiosis with the crypto scam industry. My colleagues have documented the direct mixing of North Korean funds with proceeds from fraudulent schemes like "pig butchering." A special role is played by so-called guarantee marketplaces—underground Telegram platforms in Chinese offering laundering services, technical tools, and escrow services. For example, part of the funds after the WazirX attack was consolidated on TRON and sent to addresses linked to Xinbi Guarantee and Huione Guarantee.

Fragmentation and P2P as a strategy

Instead of large transfers, fragmentation is used: stablecoins are sold through P2P marketplaces in batches of approximately $7,000 to avoid AML monitoring. Transactions are also split into amounts up to $30,000 to minimize losses in case of potential freezing. To speed up the process, pre-prepared wallets with automatic distribution are used. Endpoints include P2P platforms in South Asia and unregulated exchanges in Latin America.

My professional commentary: This new model poses an existential threat to the entire crypto industry. Once funds dissolve into the general mass of criminal flows, the link to the original attack becomes practically unprovable. Exchanges and regulators must realize: we are dealing not with isolated incidents, but with a well-oiled state machine that exploits vulnerabilities in the global financial system. Combating this will require an unprecedented level of international coordination and the implementation of fundamentally new analytical methods.